* Patches from Cisco, Apple, Oracle, others * New Trojan intercepts online banking information * Storm botnet gets profiled at Web site, and other interesting reading
The presidential primary season has “Super Tuesday” when dozens of states hold their elections simultaneously. In the world of security updates, this could be considered “Super Patch Week” with new updates from Cisco, Apple, Oracle, IBM and numerous Linux vendors. Plus, Microsoft is chiming with a warning of a new Excel flaw and the pesky Storm Worm is taking on a Valentine’s Day theme.
Cisco warns of Unified Communications Manager heap overflow flawRead what the bloggers are saying.)
Cisco Wednesday released its first new security alert of the year: a warning that its Cisco Unified Communications Manager – formerly CallManager – contains a heap overflow vulnerability in the Certificate Trust List that could allow a hacker to cause a denial-of-service attack or execute arbitrary code. NetworkWorld.com, 01/16/08. (
Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow
**********
Apple’s first security patches of 2008 fix iPhone, QuickTime
Apple has released its first security updates of the new year, fixing bugs in its QuickTime media player and iPhone and iPod touch devices. IDG News Service, 01/15/08.
Apple iPhone v1.1.3 and iPod touch v1.1.3 advisory
Apple QuickTime 7.4 advisory
US-CERT: Apple QuickTime Updates for Multiple Vulnerabilities
**********
Oracle fixes critical flaws in quarterly update
Oracle has released 26 fixes across its product line in its latest critical patch update, nine of which repair flaws that are remotely exploitable. In an advisory listing the problems, Oracle advised administrators to patch their machines as quickly as possible. IDG News Service, 01/16/08.
**********
Microsoft warns of new Excel vulnerability
Attackers are exploiting a vulnerability that lies within several versions of the Excel spreadsheet program, Microsoft warned late Tuesday. The problem in Excel allows a hacker to create a malicious Excel document that when opened can compromise a computer, Microsoft said in an advisory. The vulnerability could allow remote code to be executed on a computer, which means a user risks having their personal data exposed. IDG News Service, 01/16/08.
Microsoft advisory: Vulnerability in Microsoft Excel Could Allow Remote Code Execution
**********
IBM warns of flaw in Tivoli Storage Manager Express
IBM has issued a warning about a security flaw in Tivoli Storage Manager Express backup and recovery system that could enable unauthorized access to data stored on the system. Computerworld, 01/15/08.
IBM advisory: IBM Tivoli Storage Manager Express Heap Overflow
**********
Flash attack could take over your router
Security researchers have released code showing how a pair of widely used technologies could be misused to take control of a victim’s Web browsing experience. IDG News Service, 01/15/08.
**********
Seven new patches from Debian:
PostgreSQL 7.4 (multiple flaws)
PostgreSQL 8.1 (multiple flaws)
**********
Three new updates from Mandriva:
python (integer overflows, code execution)
**********
Three new fixes from rPath:
cairo (integer overflows, code execution)
**********
Two new updates from FreeBSD:
libc (memory corruption, data overwrite)
**********
Three new patches from Ubuntu:
**********
Today’s malware news:
New Trojan intercepts online banking information
A new Trojan program is targeting unwitting users’ bank data by intercepting account information before it is encrypted and sending it to a central attacker database. Network World, 01/14/08.
Podcast: Beware of man-in-the-middle attacks
Symantec Security Response blog: Banking in Silence
10,000 Web sites rigged with advanced hacking attack
A sophisticated hacking scheme seen early last year is affecting an increasing number of Web servers, including one owned by a major online advertising company, the chief technology officer of Finjan Software said Monday. IDG News Service, 01/14/08.
Storm Loves You – New Campaign, Valentine’s Day Theme
Welcome to “All Storm, All the Time!”, this time we delve into the malware that loves us. Arbor Networks Security to the Core blog, 01/15/08.
**********
From the interesting reading department:
My Open Wireless Network
Whenever I talk or write about my own security setup, the one thing that surprises people — and attracts the most criticism — is the fact that I run an open wireless network at home. There’s no password. There’s no encryption. Anyone with wireless capability who can see my network can use it to access the internet. Bruce Schneier’s blog, 01/15/08.
Storm botnet gets profiled at Web site
Storm, which has grown into a large remotely controlled botnet since the initial worm appeared a year ago to infect victims’ machines, is getting a graphic profile on a Web site set up to track it. Network World, 01/15/08.
Web flaw yields free MacWorld VIP pass
For the second year running, security researcher Kurt Grutzmacher has found a way to get a free “Platinum” pass to the MacWorld Conference & Expo, being held in San Francisco this week. IDG News Service, 01/16/08.
Prize for zero-day Windows flaws set at $20,000
A security research company is offering $20,000 for information on undisclosed security flaws in Microsoft’s Windows OS. IDG News Service, 01/16/08.
Two-thirds of Oracle DBAs don’t apply security patches
Oracle issues dozens of security patches every quarter, but that doesn’t mean database administrators are necessarily implementing them. Computerworld, 01/14/08.
Ikea closes global spam gap
The global furniture giant Ikea has closed a serious security gap that for an unknown period of time gave hackers and phishers a free rein to exploit the company’s mail server. Computerworld, 01/15/08.
Crime hubs can be downed by publicity
One of the best ways to fight the criminal malware networks that now populate the Internet might actually be the simplest – publicize their existence. TechWorld, 01/14/08.
Wireless LAN scan finds big security holes in NYC retailers’ wireless nets
There’s bad news for some retailers at this week’s National Retail Federation trade show in New York City, where WLAN security company AirDefense disclosed the findings of its four-day scan of local retailers’ wireless nets. NetworkWorld.com, 01/15/08.




